Threat encyclopedia
How to read detection names
Names like "Win.Trojan.Agent-1234567-0" aren't random. Here's how to read ClamAV detection names, along with the threats FileScan has actually detected, their risk level and what to do about them.
Anatomy of a detection name
Official ClamAV signatures follow the pattern Platform.Category.Name-SignatureID-Revision.
- WinPlatform
- TrojanType
- AgentName
- 1234567Signature ID
- 0Revision
- Platform
- The targeted environment or file format: Win for Windows, Doc for Word documents, Pdf for PDF, and so on.
- Type
- The malware category, such as Trojan or Ransomware.
- Name (family)
- The name of a known malware family such as Emotet. Agent or Generic are catch-all names.
- Signature ID
- The identifier within the ClamAV database.
- Revision
- The signature's revision number.
Special names
- PUA.
- Potentially Unwanted Application — tools or adware that aren't necessarily malicious.
- Heuristics.
- A warning based on file traits rather than a signature (encryption, macros, sensitive data, etc.). Not necessarily a virus.
- Eicar-Test-Signature
- A harmless test file used to check that antivirus software works.
Threats detected on FileScan
Test signatures (such as EICAR) are excluded from scan statistics like the infection rate.
| Rank | Detection name | Type | Risk | Detections |
|---|---|---|---|---|
| 01 | Eicar-Test-SignatureTest | Test file (EICAR) | 601 hits | |
| 02 | Heuristics.Structured.CreditCardNumber | Credit card numbers | 4 hits | |
| 03 | Txt.Backdoor.MetasploitPayload-9874938-0 | Backdoor | 1 hit | |
| 04 | Heuristics.Structured.SSN | US Social Security numbers | 1 hit | |
| 05 | Heuristics.Phishing.Email.SpoofedDomain | Suspected phishing | 1 hit |